Scraping public LinkedIn data while logged out sits on much firmer legal ground than most people assume, and scraping while logged in sits on much shakier ground than most people assume. That is the real split, based on two major rulings. In hiQ Labs v. LinkedIn, the Ninth Circuit held in 2019, and
Scraping public LinkedIn data while logged out sits on much firmer legal ground than most people assume, and scraping while logged in sits on much shakier ground than most people assume. That is the real split, based on two major rulings. In hiQ Labs v. LinkedIn, the Ninth Circuit held in 2019, and reaffirmed in 2022, that the Computer Fraud and Abuse Act does not cover automated collection of data that is publicly accessible without logging in. In Meta v. Bright Data, a federal judge ruled in January 2024 that a platform's Terms of Service cannot bind someone who was not logged in when they accessed public data, because they were never a "user" agreeing to those terms in the first place. Neither ruling means scraping is simply legal. hiQ itself lost on other grounds, specifically for using fake accounts to collect data that required being logged in, and GDPR adds a separate layer for personal data on people in the EU regardless of public or private status. This guide breaks down what is actually settled, what is not, and where the real risk sits in 2026.
LinkedIn scraping is the automated extraction of profile, company, or activity data from LinkedIn's website, typically using a bot, script, or browser extension rather than manual copying. Its legality in the United States currently turns heavily on whether the scraper was logged into a LinkedIn account, and thus bound by LinkedIn's Terms of Service as a contracting party, at the time the data was collected. GDPR and similar data protection laws impose separate obligations when the data concerns identifiable people in the EU or UK.
Not automatically, under current U.S. federal law, but "not a crime" is a much lower bar than "risk-free." The Computer Fraud and Abuse Act, the main federal anti-hacking statute, has been interpreted by the Ninth Circuit to not apply to scraping data that anyone can see without authentication. That removes the criminal-liability question for logged-out access to public profiles.
What remains, even for logged-out public scraping, is civil exposure: breach of contract if you agreed to terms that cover it, trespass to chattels if the scraping burdens LinkedIn's servers in a way courts recognize, and state unfair-competition claims. LinkedIn has also repeatedly used these civil theories successfully against scrapers, separate from CFAA. So "not a CFAA violation" is real and meaningful, but it is one legal question out of several, not a blanket green light. For the practical, non-legal how-to on doing this carefully, see our guide on scraping leads from LinkedIn safely and legally.
hiQ Labs scraped public LinkedIn profile data to sell workforce analytics to employers. LinkedIn sent a cease-and-desist and blocked hiQ's access. hiQ sued, arguing LinkedIn could not use the CFAA to block access to public data. The Ninth Circuit agreed in 2019, a ruling the U.S. Supreme Court left standing on remand in 2022: the CFAA's "without authorization" language does not cover data that is publicly viewable without logging in.
That sounds like a clean win for scrapers, but the case did not end there. In the same litigation, the court granted LinkedIn summary judgment on hiQ's liability for a different practice: hiQ had hired contractors to create fake LinkedIn accounts specifically to collect data that was only visible while logged in. That activity was found to breach LinkedIn's Terms of Service and support contract and unfair-competition claims. The case ultimately settled in December 2022 with a $500,000 judgment against hiQ and an injunction barring its future scraping. The lesson from the full case, not just the headline ruling: public, logged-out data collection survived the CFAA challenge, but logged-in and fake-account collection did not survive at all.
Bright Data sold access to data scraped from Facebook and Instagram, both public pages, while logged out. Meta sued arguing this violated its Terms of Service. In January 2024, a federal judge ruled in Bright Data's favor: because Bright Data was not logged in, it was never a "user" who had agreed to Meta's terms, so those terms could not bind or restrict its logged-out data collection. Meta dropped the suit the following month.
The ruling matters for LinkedIn scraping by analogy, since LinkedIn's Terms of Service work the same way, as a contract you agree to by using an account. A tool scraping public LinkedIn pages while fully logged out is not a party to that contract in the same way a logged-in user is, which weakens LinkedIn's strongest legal lever against that specific pattern. The court was explicit, though, that this does not make scraping "per se legal." Other claims, trespass, unfair competition, and platform-level technical countermeasures, remain live regardless of login status.
For almost everyone reading this, the practical risk is not a courtroom. It is your account. LinkedIn's User Agreement explicitly prohibits scraping, and enforcement happens through account restriction or termination long before it reaches litigation. If you scrape while logged in, using your own account or a browser extension riding on your session, you are a contracting party under the terms you agreed to at signup, and LinkedIn can act on that directly.
This is the same distinction that runs through export tools for Sales Navigator and LinkedIn automation more broadly: the legal question about CFAA and the practical question about whether your account survives are different questions with different answers. You can be correct that a court would not find CFAA liability and still lose your LinkedIn account for a Terms of Service violation, because LinkedIn does not need a lawsuit to restrict access.
If the people in the data are in the EU or UK, GDPR applies regardless of whether the data was technically public or whether you were logged in. Scraping profile data still counts as processing personal data under GDPR, and you need a lawful basis, most often legitimate interest for B2B outreach, along with transparency about the collection and a straightforward way for people to object or request deletion.
This is a separate legal track from the CFAA and Terms of Service questions above. A method that survives U.S. contract and hacking law scrutiny can still create GDPR exposure if it touches EU residents' data without a proper basis. Our guides on GDPR compliant lead generation and staying GDPR compliant in cold outreach cover the practical requirements in detail.
The Logged-Out Line: the clearest boundary courts have drawn in scraping law right now is whether you were logged in and bound by a platform's Terms of Service when you collected the data, not whether the data itself was public or whether a bot did the collecting. Cross that line and you move from a weak CFAA claim against you to a much stronger contract claim.
This reframes the usual question. People ask "is scraping legal" as if there is one answer. The better question is "was I a party to LinkedIn's contract when I did this." Logged-out collection of visible-to-anyone data faces the weakest legal footing against it, post-hiQ and post-Bright Data. Logged-in collection, especially through fake accounts or automation riding your session, faces the strongest footing against it, which is exactly the pattern that sank hiQ regardless of its CFAA win.
"Courts keep drawing the line at the login screen, not at the privacy settings."
None of this is legal advice for your specific situation, and case law keeps developing. Treat this as the current shape of the landscape, not a permanent rule, and consult counsel before building a scraping-dependent business on any single ruling.
The safest way to avoid this entire legal landscape is to not scrape LinkedIn at all. A licensed contact database sources and verifies data through its own methods, so you are not relying on a shifting patchwork of CFAA rulings and Terms of Service interpretations to defend your prospecting.
InboundLabs is a B2B contact database with buyer intent signals layered on firmographic data, so you can filter by industry, headcount, region, and title and build a target list without touching LinkedIn's Terms of Service at all. It holds a database of 280M verified B2B contacts with 98% email deliverability on verified contacts, plus verified direct dials, not switchboard numbers. Monthly plans, no annual lock-in, and free to start, no credit card required.
See how InboundLabs finds verified contacts instantly → inboundlabs.app
LinkedIn scraping is not a single legal question with a single answer. Courts have found that scraping publicly visible data while logged out does not violate the CFAA, and that logged-out access is not automatically bound by Terms of Service you never agreed to. But logged-in scraping, fake accounts, and session-riding automation remain squarely inside LinkedIn's contract enforcement, which is exactly what got hiQ found liable despite its CFAA win, and GDPR adds a separate layer entirely for EU residents' data. If your business depends on this gray area, talk to a lawyer, and consider whether a licensed data source removes the question altogether. Start with verified data instead, free at inboundlabs.app.
Not automatically under U.S. federal hacking law, following the hiQ v. LinkedIn ruling that the CFAA does not cover collection of publicly viewable data. It can still expose you to civil claims like breach of contract or trespass, and it almost always violates LinkedIn's Terms of Service, which can get your account restricted regardless of the criminal-law question.
The Ninth Circuit ruled the CFAA does not apply to scraping data that is publicly accessible without logging in. But the same case found hiQ liable on separate grounds for using fake accounts to collect logged-in-only data, and the litigation ended in a 2022 settlement with a $500,000 judgment against hiQ and an injunction against future scraping.
Yes, explicitly. LinkedIn's User Agreement prohibits automated data collection, and this is the mechanism LinkedIn uses most often in practice, restricting or terminating accounts, rather than pursuing federal criminal claims. This applies whether or not a court would find CFAA liability for the same activity.
Yes, if the data concerns identifiable people in the EU or UK, regardless of whether the data was public on LinkedIn or whether you were logged in. Scraping counts as processing personal data under GDPR, requiring a lawful basis and transparency obligations separate from U.S. contract and hacking law questions.
Generally, yes, from a legal standpoint. Recent rulings suggest a logged-out scraper is not bound by Terms of Service the way a logged-in account holder is, and public-data CFAA claims have failed in court. Logged-in scraping, and especially scraping through fake accounts, faces the strongest legal exposure current case law has recognized.
Yes. Legality under federal law and LinkedIn's own enforcement are separate questions. LinkedIn can restrict or terminate an account for violating its Terms of Service regardless of whether a court would ultimately find the underlying activity illegal, since Terms of Service enforcement does not require a lawsuit.
LSI keywords: LinkedIn scraping, CFAA, hiQ v LinkedIn, Meta v Bright Data, Terms of Service, GDPR, public data, web scraping law, account restriction, data collection, contract claim, trespass to chattels
Premium is for a career. Sales Navigator is for a pipeline. If you are networking, job hunting, or doing occasional business development with a handful of outreach messages a month, LinkedIn Premium Business at $59.99 a month covers it, with 15 InMail credits and who's-viewed-your-profile data. If
Most advice on raising your Social Selling Index tells you to post more, connect more, and comment more, all at once. That spreads a fixed amount of daily effort across four pillars and moves each one a little. A better method: pick your lowest-scoring pillar, work only that one with a specific
Most sales reps think LinkedIn's connection limit is a fixed number. It is not. The commonly cited ceiling in 2026 is around 100 invitations a week across Free, Premium, and Sales Navigator accounts, with some established, high-activity accounts reportedly reaching up to 200. But that number is
Sales Navigator has no export button. Not on Core, not on Advanced. LinkedIn built it that way on purpose, to keep you working inside the platform instead of pulling lists out of it. If you want your lead list as a CSV, you have exactly four real paths: copy it by hand, sync it to a CRM on the
No commitment. No credit card. Just 50 free verified contact lookups.